Live data from Hacker News

We've not been trained for this: life after the Newag DRM disclosure [video]

media.ccc.de

61–70 of 74 posts

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#61

Skilled polish hackers exposed corpo greed. Well done!

It is actually far worse than just corporate greed. It shows an embedded vulnerability into the entire supply chain, a national security issue caused by corruption.

They should get awards and payouts for bringing this to light now rather than the lives it would cost during a world war.

If the company makes it so these trains stop functioning once they are in specific locations, what determines that location? A weak GPS radio signal (which have had issues with spoofing in the past)?

What would happen if that radio signal was maliciously crafted and broadcast towards trains with targeted payloads that engage this functionality? Harvests/food stuffs rot?

This line of thought doesn't require genius level IQ, given the plots in some of the movies today even a relative dunce could compare and come up with this. Food security has been an issue for every country for millennia.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#62
post #21

shouldn't EU also investigate this a little?

The EU is not a federal government. It can investigate only if there is misuse of EU budget money or the country government is breaching it's union obligations. Otherwise, the country aligns its laws to the common european framework and then the country government is responsible for investigating when someone breaks those laws.

What about NATO?

Surely embedding a remotely triggered off-switch, as a vulnerability for military and commercial trains (and the overall supply chain logistics) would merit some kind of investigation?

Can't anyone with an antenna in a semi-close proximity spoof GPS signals that would engage these mechanisms?

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#63

Earlier quoted context omitted.

The EU is not a federal government. It can investigate only if there is misuse of EU budget money or the country government is breaching it's union obligations. Otherwise, the country aligns its laws to the common european framework and then the country government is responsible for investigating when someone breaks those laws.

What about NATO? Surely embedding a remotely triggered off-switch, as a vulnerability for military and commercial trains (and the overall supply chain logistics) would merit some kind of investigation? Can't anyone with an antenna in a semi-close proximity spoof GPS signals that would engage these mechanisms?

[dead]

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#64
post #34

Earlier quoted context omitted.

Can you really keep a lawsuit going "forever"? You'd probably run out of appeal options around 5-10 years in.

Doubtful twitter would last more than the lawsuit

Twitter was profitable for a few quarters before the purchase, and the last one was distorted by a one-time legal penalty. They weren’t printing money like Facebook but a business making profits measured in the tens of hundreds of millions can hire a lot of lawyers indefinitely.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#65

Earlier quoted context omitted.

Tenders also tend to have specific requirements and "don't sabotage the trains" seems like it would be a useful one

How do you encode that into a requirement that won’t be thrown out by the courts as libel or targetting a specific manufacturer?

It's not unfairly excluding a specific manufacturer if it's a reasonable requirement. Something like "no service vendor lock-in" and "firmware can't be silently updated remotely" would do the trick and either: 1) Newag would refuse to participate; 2) Newag would not do the same shit under the new contract; 3) Newag would do the same shit, easily found in direct breach of contract, then excluded for a few rounds of tenders on the basis of past breaches and/or active litigation.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#66

Earlier quoted context omitted.

Tenders also tend to have specific requirements and "don't sabotage the trains" seems like it would be a useful one

How do you encode that into a requirement that won’t be thrown out by the courts as libel or targetting a specific manufacturer?

It’s not uncommon for tenders to be even more specific (allegedly actually unfairly benefiting specific manufacturers), but this one seems highly functional & reasonable to the point of it being more of an oversight that it wasn’t originally included.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#67

Earlier quoted context omitted.

It's not a magic spell that works across corporate entity boundaries. The company itself must have taken a relevant contract project. There must be a clear intent to defraud the EU fund (defrauding others is not enough).

> There must be a clear intent to defraud the EU fund (defrauding others is not enough). Saying defrauding others does not seem right to me. If you defraud a distributor of EU funds, that may have impacted EU funds; they would have a claim. Do you have a source for your assertion?

I meant defrauding others who might have used EU funds to pay for your services - that's not defrauding the EU and a different court and agency will handle it.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#68

Earlier quoted context omitted.

Tenders also tend to have specific requirements and "don't sabotage the trains" seems like it would be a useful one

How do you encode that into a requirement that won’t be thrown out by the courts as libel or targetting a specific manufacturer?

Tenders very often require prior history and experience to evaluate quality, ability or plain moral suitability. In a more publicly visible industry you see this, where a given banker or bank cannot get a license for some operations, Revolut for example.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#69
post #41

As much as I support and vouch for the guys. Go public earlier is BS - they went public a year ago when it was clear there is political change in PL. If they would go public in before government change it could have been tragic ( company and company ownership is tightly coupled with prev political power). If previous political power would stay in power I do not believe they would go public. As much as they are showin…

Are you sure? I thought the trains were part of of Dolneslaska which means local government, not central one. As far as I know there were no voivodeship changes.

I think the lack of traction is endemic and happens regardless of current political power. This is because one of the issues they complain about was how hard was it to explain to journalists. Journalists did not get it and neither did the people. Even the Pegasus affair did not go far with the current legislature. In a more dishonest note, they should have pulled a Russian conspiracy theory on it and it suddenly would be all over the news. As it was done on home turf it just is not so serious. Just look at how the Americans do with the Chinese, there might even be nothing but it is taken seriously.

Re: We've not been trained for this: life after the Newag DRM disclosure [video]

#70

Skilled polish hackers exposed corpo greed. Well done!

It is actually far worse than just corporate greed. It shows an embedded vulnerability into the entire supply chain, a national security issue caused by corruption. They should get awards and payouts for bringing this to light now rather than the lives it would cost during a world war. If the company makes it so these trains stop functioning once they are in specific locations, what determines that location? A weak G…

Governments don't care about saving lives, except their own.
Post reply on HN